Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In this blog, we deep-dive into SilabRAT and look at some of its interesting capabilities.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
the developer's stated plan to inject code into Electron-based wallet apps such as Ledger Live and Trezor Suite
The author has written in forum posts future plans to implement fully customizable injection capabilities targeting Electron-based applications... injecting malicious code directly into their Electron processes.
SilabRAT utilizes an additional DLL named “APPB.dll” to employ the widely utilized technique of COM elevation to bypass ABE, where it decrypts the key by creating an instance via the GoogleChromeElevationService.
It pairs those with the usual commodity-RAT toolkit: Keystroke logging and clipboard capture
A new remote access trojan sold on dark web forums has been built to drain cryptocurrency, hijacking victims' logged-in sessions to slip past passwords and multi-factor checks. | The second, browser-profile cloning, goes beyond stealing cookies. Modern sites tie sessions to a device fingerprint or IP, so SilabRAT copies the entire browser profile, including extensions, storage and fingerprinting traits, to the attacker's system to revive the session intact.
An “AutoWallet” module runs in the background and tries to crack passwords on any cryptocurrency wallets it finds. It reuses passwords harvested from the victim’s browser to unlock encrypted wallets.
To stay hidden, SilabRAT tampers with the Anti-Malware Scan Interface and adds anti-forensic tricks.
The current implementation of the defense evasion technique is limited to straightforward bypasses targeting the Anti-Malware Scan Interface (AMSI). Specifically, the method employs a simplified approach to interfere with the AmsiScanBuffer and AmsiScanString functions...
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as background/reference malware associated with hVNC/browser-cloning tradecraft, not as a confirmed payload in this incident.
A RAT associated here with browser-cloning attacks and behavior similar to hidden desktop and browser-theft activity; mentioned only for comparison.
Mentioned only as related reading; no operational connection to the described campaign is provided in the content.
Commercial remote access trojan sold as a subscription service that provides live remote control, keystroke logging, clipboard monitoring, payload delivery, HVNC, session hijacking, persistence, anti-forensics, and cryptocurrency wallet theft including password cracking of discovered wallets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.